More than 100 UK arrests in massive international bank 'ispoof' fraud probe involving FBI & Met


AN INTERNATIONAL one-stop bank spoofing website, suspected of being run from the UK, has been taken down in the country’s biggest ever fraud operation.

More than 200,000 potential victims in the UK alone were directly targeted through the fraud website iSpoof.

At one stage, almost 20 people every minute of the day were being contacted by scammers hiding behind false identities using the site.

They posed as representatives of banks including Barclays, Santander, HSBC, Lloyds, Halifax, First Direct, Natwest, Nationwide and TSB.

Scotland Yard’s Cyber Crime Unit worked with international law enforcement, including authorities in the US and Ukraine, to dismantle the website this week.

Earlier this month the suspected organiser of the website was arrested in East London.

He was charged on November 7 with with making or supplying articles for use in fraud (S7 of the Fraud Act), participating in activities of an organised crime group (S45 of the Serious Crime Act) and proceeds of crime matters, and remanded in custody.

A woman, aged 28, from Lower Clapton, was arrested on 6 November on suspicion of fraud by false representation and proceeds of crime matters and has been bailed pending further enquiries.

A woman, aged 39, from Hackney, was arrested on 7 November on suspicion of fraud by false representation and proceeds of crime matters and has been bailed pending further enquiries.

The Met police described the arrests as a crucial phase in a world-wide operation, which has been running out of the public eye since June 2021, targeting a suspected organised crime group.

iSpoof enabled criminals to appear as if they were calling from banks, tax offices and other official bodies as they attempted to defraud victims.

Victims are believed to have lost tens of millions of pounds while those behind the site earned almost £3.2 million in one 20 month period.

Detective Superintendent Helen Rance, who leads on cyber crime for the Met, said: “By taking down iSpoof we have prevented further offences and stopped fraudsters targeting future victims.

“Our message to criminals who have used this website is we have your details and are working hard to locate you, regardless of where you are.”

Commissioner Sir Mark Rowley said: “The exploitation of technology by organised criminals is one of the greatest challenges for law enforcement in the 21st century.

“Together with the support of partners across UK policing and internationally, we are reinventing the way fraud is investigated. The Met is targeting the criminals at the centre of these illicit webs that cause misery for thousands.

“By taking away the tools and systems that have enabled fraudsters to cheat innocent people at scale, this operation shows how we are determined to target corrupt individuals intent on exploiting often vulnerable victims.”

The Met’s Cyber and Economic Crime Units co-coordinated the operation with Europol, Eurojust, the Dutch authorities and the FBI.

In the UK, more than 100 people have been arrested, the vast majority on suspicion of fraud.

iSpoof allowed users, who paid for the service in Bitcoin, to disguise their phone number so it appeared they were calling from a trusted source.

This process is known as ‘spoofing’.

Criminals attempt to trick people into handing over money or providing sensitive information such as one time pass codes to bank accounts.

The average loss from those who reported being targeted is believed to be £10,000.

In the 12 months until August 2022 around 10 million fraudulent calls were made globally via iSpoof, with around 3.5 million of those made in the UK.

Of those, 350,000 calls lasted more than one minute and were made to 200,000 individuals.

Losses reported to Action Fraud as a result of the calls and texts via iSpoof is around £48 million.

Because fraud is vastly underreported, the full amount is believed to be much higher.




The Met, which has worked closely with the Cyber Defence Alliance and UK Finance, is asking anyone who believes they were contacted as part of a scam where a number was spoofed to report this online via Action Fraud.

The Met’s Cyber Crime Unit began investigating iSpoof in June 2021 under the name of Operation Elaborate.

It was created in December 2020 and had 59,000 user accounts.

Investigators infiltrated the site and began gathering information alongside international partners.

The website server contained a treasure trove of information in 70 million rows of data.

Bitcoin records were also traced.

Because the pool of 59,000 potential suspects is so large, investigators are focusing first on UK users and those who have spent at least £100 of Bitcoin to use the site.

A wave of UK arrests followed with details of other suspects passed onto law enforcement partners in Holland, Australia, France and Ireland.

There are more than 70,000 numbers that have been contacted via iSpoof that the Met has linked to an identified suspect.

We are actively contacting those numbers this week asking owners to visit our website for more information and to report any fraud losses online.

Eurojust President Mr Ladislav Hamran said: “As cybercrime knows no borders, effective judicial cooperation across jurisdictions is key in bringing its perpetrators to court. Eurojust supports national authorities in their efforts to protect citizens against online and offline threats, and to help see that justice gets done.”

Europol Executive Director Ms Catherine De Bolle said: “The arrests today send a message to cybercriminals that they can no longer hide behind perceived international anonymity. Europol coordinated the law enforcement community, enriched the information picture and brought criminal intelligence into ongoing operations to target the criminals wherever they are located. Together with our international partners, we will continue to relentlessly push the envelope to bring criminals to justice.”

Commander Nik Adams, from the City of London Police, said: “As the national lead force for fraud, we have coordinated activity across the country with other police forces and Regional Organised Crime Units (ROCUs) to provide a co-ordinated response to support the Metropolitan Police Service with their action and help make this operation a success. Our collaborative approach has supported this operation, which is also underpinned by our work with the National Economic Crime Centre (NECC) within the National Crime Agency.

“Collaborative and proactive operations like this to tackle fraud are vitally important in clamping down on criminals and preventing innocent members of the public from being targeted for their hard-earned money.”

Marijus Briedis, a cybersecurity expert at virtual private network provider NordVPN, said: “Public confidence in the ability of law enforcement to tackle this kind of organised crime is unacceptably low. These kinds of spoofing attacks, much like phishing, are now a routine part of everyday life for consumers. It should never have been allowed to get this far.

“Many of iSpoof’s customers would have been highly professional gangs who see these tools as worthwhile investments. Those responsible need to be made examples of and new powers introduced if necessary to enable the police to increase the pace at which they can smash these organisations. The end of iSpoof is fantastic news but there are thousands more people out there like them.

“Consumers need to remain vigilant. The only way to stay safe online and on mobile phones is to refuse to give out personal information to anyone who calls you. Unfortunately, many companies still do this on outbound calls, which ultimately gives criminals an easier ride.”